CVE-2026-86688 | team-alembic ash_authentication up to 0.2.0/4.14.x/5.0.0-rc.0/5.0.0-rc.13 Session AshAuthentication.Plug.Helpers.store_in_session session fixiation
A vulnerability was found in team-alembic ash_authentication up to 0.2.0/4.14.x/5.0.0-rc.0/5.0.0-rc.13. It has been declared as critical. This affects the function AshAuthentication.Plug.Helpers.store_in_session of the component Session Handler. Such manipulation leads to session fixiation.
This vulnerability is traded as CVE-2026-86688. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More